GPO Sprawl


i took position allowed container admins (ca) add/adjust/create gpos. out of control. company has 138 ca accounts, , 636 gpo's listed. it's task under control. question pretty broad. start? have plan of attack i'd love hear others see their point of view. 

deann

i took position allowed container admins (ca) add/adjust/create gpos. out of control. company has 138 ca accounts, , 636 gpo's listed. it's task under control. question pretty broad. start? have plan of attack i'd love hear others see their point of view. 

deann

if in situation, following

  • backup gpo in case...
  • check delegation (yes, difficult task !) , remove desired users (if applicable)

ref: how view or delete active directory delegated permissions (en-us)

http://social.technet.microsoft.com/wiki/contents/articles/6477.how-to-view-or-delete-active-directory-delegated-permissions-en-us.aspx

  • check group policy creator owners group - remove users (if applicable)
  • check domain admins group - remove users (if applicable)
  • restrict users gpmc
  • create domain level policy , link ous
  • unlink unwanted gpos on ous 1 one
  • instruct admins not create or link gpos without approval during gpo sanitizing phase
  • before access permission revocation, make note of permissions set on containers, ids etc.. screen shots come in handy well

hth


i not represent organisation work for, opinions expressed here own.

this posting provided "as is" no warranties or guarantees , confers no rights.

- .... .- -. -.- ... --..-- ... .- -. - --- ... ....



Windows Server  >  Group Policy



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file